CVE-2022-50945 MEDIUM

CVE-2022-50945: WordPress 3dady Real-Time Web Stats 1.0 Stored XSS

Vendor 3Dady
Product real-time web stats
Weakness CWE-79 · XSS
Published May 10, 2026
Last update May 26, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields via the plugin options panel to execute arbitrary code when the page is viewed.

Explanation of Vulnerability in Simple Terms

02Summary

A cross-site scripting (XSS) vulnerability in 3dady Real-Time Web Stats allows an attacker to inject malicious scripts that execute in other users' browsers. The vulnerability requires low-level authentication and user interaction, such as clicking a malicious link. The impact is limited to the scope of the vulnerable component.

What an attacker can do

03Attacker Capabilities

Inject and execute malicious JavaScript in other users' browsers when they interact with the affected component.

Potential impact on your site

04Site Impact

Users viewing the affected component may have their sessions compromised or be redirected to malicious sites.

Conditions required to exploit

05Prerequisites

Attacker must have low-level authentication and the victim must click a malicious link or visit a crafted page.

Key dates

06Disclosure timeline

May 10, 2026 CVE published
May 26, 2026 Record updated

Related vulnerabilities

08Related CVE